← Back

CVE-2017-15091

nvd nist
Published: Jan 23, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.1
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Exploitability: 2.8 / Impact: 4.2
Source: NVD

Description

An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing check allows an attacker with valid API credentials to flush the cache, trigger a zone transfer or send a NOTIFY.

Affected (2)

1 product
Authoritative
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Powerdns
From 3.0 to 3.4.11
From 4.0.0 to 4.0.4

References (4)

Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.